CVE-2026-51662
moderateUnauthenticated information disclosure in TOTOLINK T6 router
TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 have an improper access control flaw (CWE-284) in the getCloudSrvCheckStatus function of the device's web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint over the network. Successful exploitation discloses the router's cloud firmware check status information only; the CVSS 3.1 vector (C:H/I:N/A:N) indicates no impact on data integrity or availability. Only the TOTOLINK T6 on the named firmware build is identified in the advisory, and whether other firmware versions are affected is not stated. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and the 0.4% EPSS suggests low near-term exploitation risk.
What to do: Do not expose the T6's web management interface to the WAN (avoid port-forwarding ports 80/443 to the router), and restrict remote management with firewall rules if it is needed. Check the running firmware version in the router's administration page and upgrade to the latest firmware TOTOLINK publishes for the T6 when available. Given the information-disclosure-only impact, absence of a known PoC, and the 0.4% EPSS, treat this as routine hardening rather than an emergency.
| TOTOLINK T6 wireless router | 4.1.5cu.748_B20211015 (version named in the advisory; scope of other builds not stated) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.